From 906b6cabbcd5d507ac96cc79e62d394d5e5011e1 Mon Sep 17 00:00:00 2001 From: Silvio Rhatto Date: Wed, 23 May 2018 15:06:44 -0300 Subject: Automatically generate keys and add into hiera secret config at newnode --- share/hydra/newnode | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) (limited to 'share/hydra/newnode') diff --git a/share/hydra/newnode b/share/hydra/newnode index 9926a71..96861f6 100755 --- a/share/hydra/newnode +++ b/share/hydra/newnode @@ -77,6 +77,25 @@ fi mkdir -p $HYDRA_FOLDER/puppet/config/secrets/node cp $YAML $HYDRA_FOLDER/puppet/config/secrets/node/$NODE.yaml +# Generate keys +hydra $HYDRA newkeys all $NODE + +# Add OpenPGP key ID into secret node config +KEYID="`keyringer $HYDRA decrypt nodes/$NODE/gpg/key.pub 2> /dev/null | gpg --with-colons 2> /dev/null | grep ^pub: | cut -d : -f 5`" +echo "nodo::subsystem::backup::encryptkey: '$KEYID\"" >> $HYDRA_FOLDER/puppet/config/secrets/node/$NODE.yaml + +echo "" >> $HYDRA_FOLDER/puppet/config/secrets/node/$NODE.yaml + +# Add OpenPGP passphrase into secret node config +keyringer $HYDRA decrypt nodes/$NODE/gpg/key.passwd | \ +hydra fluxo eyaml $NODE encrypt --stdin -o block -q -l nodo::subsystem::backup::password >> $HYDRA_FOLDER/puppet/config/secrets/node/$NODE.yaml + +echo "" >> $HYDRA_FOLDER/puppet/config/secrets/node/$NODE.yam + +# Add Borg passphrase into secret node config +keyringer $HYDRA decrypt nodes/$NODE/borg/key.passwd | \ +hydra fluxo eyaml $NODE encrypt --stdin -o block -q -l nodo::subsystem::backup::borg::password >> $HYDRA_FOLDER/puppet/config/secrets/node/$NODE.yaml + # Add to git ( cd $HYDRA_FOLDER/puppet -- cgit v1.2.3